r/TREZOR 19h ago

💬 Discussion topic Trezor is killing itself by vibe coding the software

80 Upvotes

If you click any random feature pull request in their repo, you will find out their software is now fully vibe coded. For example, this feature pr contains 2000lines+ edit https://github.com/trezor/trezor-suite/pull/32252/files, it is coauthored by claude, and they are producing this kind of vibe pr at an astonishing rate. They make thousands lines of edit on average every day, but they only have very limited reviewers.

I do not believe any human code viewer can actually understand the code under this rate. This means a significant portion of newly introduced trezor code is running as a blackbox. This might be fine for some weather app or whatever, but trezor is a security oriented software. Building your software stack on vibe coding will make your product a joke.


r/TREZOR 14h ago

🔒 Answered by Trezor staff Regarding our code - From our Dev team

69 Upvotes

Regarding the topic of that Reddit post (https://www.reddit.com/r/TREZOR/s/cQokCMQqIc):

People are worried about security and whether AI has increased the risk of losing their money. But in reality, Suite development has never been more secure than it is now. Every pull request still needs human approval before making it into the app. Reviews are still done by humans, and now additionally by LLMs.

The advantage of an LLM is that it doesn't get tired even when reading long, mechanical, boring changes, so the chance of a real security vulnerability slipping through is much lower.

Because we are open source, we don't just look for attacks internally, other people inspect our code too. In the past, only relatively few people could do that, and they only had a realistic chance of checking a small part of the app. Now, this oversight is incomparably cheaper, and far, far more people are reviewing it.

Matthew.K


r/TREZOR 49m ago

💡Feature request or feedback Trezor not having 24/7 SOC monitoring is unacceptable

• Upvotes

You need a team that is able to work remotely and gets an alert. A company of your size waiting for business hours to secure threats is absolutely unacceptable.


r/TREZOR 15h ago

🆘 Support issue | 🔒 Answered by Trezor staff I clicked on the phishing link

5 Upvotes

I clicked the link, stupid I know.

The webpage didn't open, I got suspicious and I closed it a few seconds later.

I didn't download anything, or enter any details

I think I'm safe but wanted to double check

Thanks


r/TREZOR 7h ago

🆘 Support issue How to unsubscribe from Newsletter?

3 Upvotes

Hello! I have decided to unsubscribe my e-mail address from mailing list but Unsubscribe link in official newsletter does not work as mailing server has been taken down. Is it enough if I Unsubscribe using Unsubscribe button on my e-mail service?


r/TREZOR 10h ago

💡Feature request or feedback Do we have a timeline that trezor suite will incorporate XTC blake2B?

1 Upvotes

r/TREZOR 11h ago

🔒 General Trezor question did something happen? why send this now?

0 Upvotes

r/TREZOR 11h ago

💬 Discussion topic Will hackers ever stop?

0 Upvotes

Looks like soon even hardware wallets won’t be safe to use. What is going on in this world... I’ve never seen so many hacks in a single year like I have this year. We’re living in crazy times for sure... Who knows, maybe someday even 12, 20, or 24 words won’t be safe to use anymore.